LWN.net Logo

asterisk: multiple vulnerabilities

Package(s):asterisk CVE #(s):CVE-2013-5641 CVE-2013-5642
Created:August 30, 2013 Updated:September 16, 2013
Description:

From the Mandriva advisory:

A remotely exploitable crash vulnerability exists in the SIP channel driver if an ACK with SDP is received after the channel has been terminated. The handling code incorrectly assumes that the channel will always be present (CVE-2013-5641).

A remotely exploitable crash vulnerability exists in the SIP channel driver if an invalid SDP is sent in a SIP request that defines media descriptions before connection information. The handling code incorrectly attempts to reference the socket address information even though that information has not yet been set (CVE-2013-5642).

Alerts:
Mandriva MDVSA-2013:223 2013-08-30
Debian DSA-2749-1 2013-09-02
Mageia MGASA-2013-0266 2013-08-30
Fedora FEDORA-2013-15567 2013-09-14
Fedora FEDORA-2013-15560 2013-09-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds